Web

How to Create an FTP Account in cPanel and Connect with FileZilla

Talha Aslan 19 min read 1 views

What is a cPanel FTP account and what is it for?

A cPanel FTP account is a separate username and password that lets you upload and download files in one specific folder of your hosting account with a client such as FileZilla. You give a developer, designer or your own laptop access to the right directory without sharing your main cPanel password.

In this guide, we walk through the FTP Accounts screen in cPanel step by step. Then we cover connecting with FileZilla, encrypted connection options, common error codes and the security rules that matter. We are a digital marketing and web team, not a hosting company. So we base every screen name and setting on the official cPanel documentation.

We also draw an honest line in each section. On shared hosting, the FTP server software, port ranges and firewall belong to your hosting provider, not to you. You, in turn, create the account, configure the client and manage access. When a fix needs a server setting, opening a support ticket is the fastest route.

Which decisions should you make before creating the account?

Creating an FTP account takes about a minute. However, the wrong directory or an account that never expires can cause trouble months later. That is why we suggest you answer these questions before filling in the form:

  • Who will use the account: you, a developer or an automated backup tool?
  • Which folder will they work in: the whole site, only a theme folder or a subdomain?
  • How long will access last: a one-time migration or ongoing maintenance?
  • Does your host support encrypted FTP (FTPS), and do you have SSH access?
  • Who will delete the account when the work ends, and on what date will you check?

Your answers decide the directory and quota fields in the form. For example, a developer who only updates one plugin does not need the root directory. On the other hand, a team migrating a full site may need wider access. In that case, keep the window short and close the account as soon as the work ends.

Finally, take a fresh backup of your site before you start. A file uploaded to the wrong folder can overwrite an existing one. If you have no backup routine yet, read our website backup strategy guide first.

How do you create a cPanel FTP account step by step?

According to the official cPanel FTP Accounts documentation, the interface lives under the Files section. The exact look also depends on your theme. Still, the order of the steps stays the same:

  1. Log in to cPanel and type "FTP" in the search box, or click FTP Accounts in the Files section.
  2. Enter a username in the Log In field. Pick a short name that describes the job, such as "theme" or "migration".
  3. Next, select the domain from the Domain menu. This way, the username combines with this domain to form the full login name.
  4. Then fill in the Password fields. If you prefer, click Password Generator to create a strong password.
  5. Check the Directory field. cPanel fills it in automatically, so change the path to match the job.
  6. Enter a disk limit in the Quota field, or select Unlimited.
  7. Click Create FTP Account. The new account then appears in the list at the bottom of the page.

After you create the account, you will also see a link to configure an FTP client next to it. According to the official documentation, cPanel lets you download ready-made configuration files for some clients there. In practice, though, entering the settings by hand is often clearer. We show that below with FileZilla.

What do the fields on the FTP Accounts screen mean?

Put simply, each field in the form decides what the account can touch. So instead of filling them in and moving on, it helps to know the effect of each one. The table below sums them up:

FieldWhat it controlsWhat to watch
Log InThe account's usernameThe full login is the username plus the domain (in the form user@example.com).
DomainThe domain the account belongs toIf you host several sites, make sure you pick the right domain.
PasswordThe login passwordAim for a strong rating and never reuse the password elsewhere.
DirectoryThe top folder the account can seeThe account cannot leave this folder; per the docs, symlinks cannot push uploads outside it either.
QuotaDisk space the account may usePer the docs, servers running ProFTPD cannot apply quotas.

Above all, the most important field in the table is Directory. According to the current cPanel docs, the system fills it with a new folder path under public_html based on the domain and username you entered. In other words, if you change nothing, the account opens an empty subfolder. If the person logs in and cannot see the site files, this is the first place to look.

The username format also causes confusion. If you type only "theme" in the client, the login fails. On most cPanel servers you need the full name, such as "theme@example.com".

What is the difference between the main FTP account and an extra one?

You will see two kinds of FTP accounts in cPanel: special accounts that exist even if you never create them, and accounts you add yourself. According to the official docs, you cannot modify or delete the special accounts. One of them is the main FTP account, which uses your cPanel username. The second, meanwhile, is the logs account, which downloads raw access logs.

FeatureMain FTP accountExtra cPanel FTP account
Who creates it?cPanel, automaticallyYou, from the FTP Accounts screen
Access scopeAll account files, including outside public_htmlOnly the chosen directory and below
PasswordYour main cPanel passwordA separate password for this account
Can you delete it?NoYes, at any time
Who should get it?Nobody elseThird parties, for temporary work

In short, the main account is a key ring that opens every door in the house. Because its password is also your cPanel login, anyone who holds it can reach your email, databases and domain settings. That is why you should always create an extra account when you work with someone outside your team.

An extra account, by contrast, is the key to a single room. When the work ends, taking that key back, which means deleting the account, is far easier than changing your main password.

How should you choose the directory and quota?

When you pick a directory, aim for the narrowest folder that still gets the job done. This principle is called least privilege, and it applies to FTP as much as anywhere else. For example, a designer who only edits theme files on a WordPress site gets the theme folder. A team moving the entire site, on the other hand, gets public_html.

Common choices look like this:

  • public_html: all files of the main site. It suits migrations or general maintenance, but it is broad access.
  • A subfolder inside public_html: enough for one plugin, one theme or a campaign landing page.
  • An addon domain's own folder: for a second site on the same cPanel account, choose that site's folder.
  • A separate upload folder: if a client or partner only needs to drop files, create a folder that never touches site files.

The point of a quota is to stop an uncontrolled upload from filling the disk of the whole account. For example, a person who only uploads theme files does not need unlimited space. That said, remember that a per-account quota never exceeds your hosting plan's total disk limit.

Also, keep the note from the official docs in mind: if your server runs ProFTPD, the quota field has no effect. If you do not know which FTP server your host runs, ask them.

How do you connect to a cPanel FTP account with FileZilla?

FileZilla is a free and widely used FTP client for Windows, macOS and Linux. We recommend the Site Manager over the Quickconnect bar, because you can only choose the encryption setting explicitly there. Follow these steps:

  1. Open Site Manager from the File menu and click New site.
  2. Leave the protocol set to "FTP - File Transfer Protocol".
  3. In the Host field, enter the FTP server address your host gives you. In most cases, that is your domain or ftp.example.com.
  4. Enter 21 in the Port field, or leave it blank.
  5. Under Encryption, select "Require explicit FTP over TLS".
  6. Set the logon type to "Normal" and enter the full login name and password.
  7. Click Connect and read the certificate window that appears on the first connection.

Here is a summary of the settings:

Protocol    : FTP
Host        : ftp.example.com
Port        : 21
Encryption  : Require explicit FTP over TLS
Logon type  : Normal
User        : theme@example.com
Password    : (the password you set in cPanel)

Once connected, the right pane shows only the directory you assigned to the account. If the files you expect are missing, the problem is not the connection. Instead, check the directory setting.

What is the difference between FTP, FTPS and SFTP?

These three acronyms look alike, but they differ a lot in security. Classic FTP is an old protocol defined in RFC 959, and it sends the username and password across the network in plain text. FTPS, on the other hand, wraps that same FTP in TLS encryption. SFTP, despite its name, is not FTP at all. Instead, it is a separate file transfer method that runs over SSH.

MethodEncryptionDefault portWho uses it in cPanel?
FTPNone, password in plain text21The option to avoid
FTPS (explicit TLS)TLS on control and data channels21 (upgraded with AUTH TLS)Extra FTP accounts too, if the server supports it
SFTPWhole session over SSH22 (your host may change it)The cPanel account user with SSH enabled

The cPanel firewall documentation recommends the more secure SFTP over SSH instead of FTP. However, SFTP requires SSH access. Meanwhile, many shared hosting plans keep SSH off or only turn it on by request. In addition, extra FTP accounts usually are not SSH users, so in most cases you use SFTP with the main cPanel user.

So the practical order is simple. If you have SSH access and work alone, use SFTP. If you give a third party limited access, use FTPS with explicit TLS. Use plain FTP only when nothing else works, and only briefly. To keep SSH itself safe, see our swap file and SSH hardening guide.

Why choose explicit TLS, and what if a certificate warning appears?

With explicit TLS, the client connects to the standard port 21 and then upgrades the session to an encrypted one with the AUTH TLS command. RFC 4217 defines this method, and most modern FTP servers support it. Implicit TLS, by contrast, is an older approach where the connection starts encrypted and needs a separate port.

FileZilla's default option uses explicit TLS only if available. If the server offers no TLS, that option quietly falls back to an unencrypted session. Therefore we recommend the "Require" option instead. If the server lacks TLS, FileZilla refuses to connect and you notice the problem right away.

On the server side, the decision belongs to your host. In WHM's FTP Server Configuration screen, a server running Pure-FTPd offers TLS support values of "Disabled", "Optional", "Required (Command)" and "Required (Command/Data)". Consequently, on shared hosting you cannot change this. You can only ask your host whether TLS is on.

On the first connection, FileZilla shows a certificate window. On shared hosting, the certificate often belongs to the server's own hostname rather than your domain. As a result, you may see a name mismatch warning. In that case, the fix is to enter the server hostname your host provides in the Host field. If you are unsure who owns the certificate, ask support before you accept it. To check the certificate on your own domain, use our SSL checker.

What are passive and active mode, and which should you pick?

FTP works over two separate connections. First, commands travel over the control connection on port 21. Directory listings and the files themselves, however, flow over a separate data connection. Active and passive mode decide which side opens that data connection.

  • In active mode, the server connects back to a port the client announces. Home and office routers and firewalls often block that incoming connection.
  • In passive mode, the client opens the connection to a port the server announces. As a result, it usually works fine for users behind NAT.

In practice, you want passive mode, and FileZilla uses passive mode by default. You can find the setting under Edit, then Settings, then Connection and FTP. In Site Manager, you can also set it per site on the Transfer Settings tab.

Passive mode does have one condition, though. The port range the server uses for passive connections must be open in the server firewall. Specifically, the server administrator sets that range. So if your login succeeds but no file list appears, the cause usually lies in that range, and the fix is in your host's hands, not yours.

Moreover, with an encrypted session, routers and firewalls cannot read the FTP commands inside. That means some network "helper" features that assist plain FTP stop working under TLS. This is normal, so do not worry. The right fix is not to turn encryption off but to configure passive mode properly on the server.

Why does the 530 login error appear, and how do you fix it?

530 is the reply code that RFC 959 defines as "Not logged in". In other words, the server has refused to start a session with the credentials you sent. This error almost always comes from the client side, so you should check your own details first.

Here are the common causes, in the order to check them:

  1. The username is incomplete. For extra accounts, use the full login such as "theme@example.com", not just "theme".
  2. The password was pasted incorrectly. Even a stray space at the start or end breaks the login, so try typing it by hand.
  3. Also, the account may belong to a different domain. Check the full name in the FTP Accounts list.
  4. You changed the password recently and FileZilla still uses the old one. Update the entry in Site Manager.
  5. The server requires encryption while you try a plain connection. Check the encryption setting.

If these steps do not help, reset the account password with Change Password in cPanel and try again. If the login still fails, the server may have blocked your IP after too many failed attempts. We cover that in the firewall section below.

How do you fix timeouts and directory listing errors?

A timeout comes in two forms, and telling them apart speeds up the fix. In the first, the client never reaches the server at all. In the second, the login succeeds, but FileZilla reports that it failed to retrieve the directory listing.

If you cannot connect at all, run these checks first:

  • Verify the server address. You can confirm that your domain's DNS records point to the right server with our DNS lookup tool.
  • Try another network. For example, if a phone hotspot works, the problem is most likely your office firewall.
  • Try the server's IP address directly. If you changed DNS recently, this clears things up.

If the login works but no listing appears, the problem most likely sits in the data connection. First, confirm that you are in passive mode. Then retry without changing the encryption setting. If the issue persists, send your host the time of the attempt and the lines from FileZilla's message log.

In RFC 959, code 425 means the data connection could not open. Code 421, on the other hand, means the service is not available and the server is closing the control connection. Adding these codes to your support ticket helps your host find the cause faster.

What should you do if a firewall blocks the FTP connection?

A firewall problem can sit in three places: on your computer, on your local network or on the server. The quickest way to tell which is to connect from a different network with the same settings.

Security software on your computer may block FileZilla's outgoing connections. In that case, allow FileZilla in its settings. On corporate networks, outbound FTP traffic may be off on purpose. Then you need to talk to your network administrator.

On the server side, two mechanisms are common. On cPanel servers, a protection called cPHulk can temporarily block IP addresses after repeated failed logins. Some servers also run a firewall such as CSF, which does a similar job; our CSF firewall guide explains it in detail. Either way, lifting the block is the server administrator's job.

When you open a ticket, include your public IP address, which you can find with our IP lookup tool. Also add the time of the error and the full name of the FTP account. If you manage your own VPS, you need to open port 21 and the passive port range in the firewall. That said, rather than testing an unfamiliar rule on a live server, hand the task to an experienced admin.

Which rules keep a cPanel FTP account secure?

An FTP account gives direct write access to your site files. A compromised account can lead to malicious uploads or a broken site. That is why we suggest you turn the following rules into habits:

  • Use a unique, long password for every account. Our password generator does the job.
  • Create a separate account for each person. If several people share one account, you cannot tell who did what.
  • Limit the directory to the narrowest folder that works. Grant the root directory only when it is truly needed.
  • Avoid plain FTP. Use FTPS with explicit TLS, or SFTP.
  • Delete the account when the work ends. Accounts left open without an end date are doors nobody remembers.
  • Do not leave passwords in plain text in email or chat history. Use a password manager instead.
  • Do not turn on anonymous FTP. The WHM documentation also warns that anonymous FTP endangers server security.

These rules are only one part of a wider web security approach. For application-level risks, see our OWASP Top 10 guide. If you wonder how accounts stay apart on a shared server, our CageFS article explains it.

How should you give temporary access to an agency or developer?

When you work with an outside team, the goal is to get the work done while keeping risk small. Sharing the main cPanel password feels easy, but it also opens email, databases and domain settings. Therefore, an extra FTP account is almost always the better choice.

When we ask clients for access on web projects, we also suggest this method:

  1. Create a dedicated account and give it a name that reflects the job or the team.
  2. Limit the directory to the folder the job needs.
  3. Send the username and password through separate channels, for example the name by email and the password by phone.
  4. Put the end date of the work in your calendar.
  5. When the work ends, delete the account, or at least change its password.
  6. Back up the changes before you delete anything.

In addition, keep a list of who has which access. For agencies that manage many client accounts, our cPanel reseller hosting guide describes a different model. If you plan to hand your site's design or development to us, our web design service plans access along these same principles.

How do you delete an FTP account or change its password and quota?

The list at the bottom of the FTP Accounts screen shows management options next to each account. According to the official docs, you can change the password and the quota separately.

To change the password, click Change Password on the account's row, type the new password twice and save. To change the quota, use Change Quota, enter the new limit or choose unlimited. The change applies from the next connection.

Deleting needs more care, because cPanel offers two different options:

  • Delete Account: removes only the FTP account and leaves the files alone.
  • Delete Account and Files: removes the account together with the files in its home directory.

If the account's directory is public_html, the second option can wipe your whole site. So when you remove a temporary account, deleting only the account is almost always enough. If you do want the files gone too, back up first and make sure nothing else lives in that folder.

Finally, the special accounts show no delete option in this list. Since the main account's password matches your cPanel password, you change it only by changing the account password itself.

When should you use something other than FTP?

FTP is not the best tool for every job. For a quick change to a few files, cPanel's File Manager is often enough and needs no extra account. For moving large batches of files or regular uploads, however, a desktop client is more comfortable.

In contrast, for teams that write code, version control is the safer path. If you track changes with Git and deploy them in a controlled way, you can see which file changed and when. Our Git and GitHub guide covers the basics.

Here is a short road map:

  • Fix a single file: cPanel File Manager.
  • Limited folder access for an outsider: an extra FTP account with FTPS.
  • Full control of your own server: SSH and SFTP.
  • Ongoing team development: Git-based deployment.

This way, you use FTP only where it truly fits, and under control. Also, the fewer accounts you have, the lower the risk of forgotten access.

When should you leave the job to your hosting provider?

Creating an FTP account, changing its password and setting up the client are your tasks. Some problems, however, only someone with administrator access to the server can fix. Knowing that line saves you hours of trial and error.

We recommend opening a support ticket right away in these cases:

  • You cannot connect from several networks despite correct details.
  • The login works but no listing appears with any setting; this usually points to the passive port range.
  • The server offers no TLS and you want an encrypted connection.
  • You suspect the server blocked your IP address.
  • You want SSH access turned on for SFTP.

If you run your own VPS, these settings are yours to make. Even so, changing firewall rules on the server of a live online store carries real risk. For that kind of work, a host that offers managed service is often the more economical choice. To pick the right plan, see our guide to choosing web hosting.

A short checklist for setting up a cPanel FTP account

If you want the whole guide in one list, follow this order when you open and close a cPanel FTP account. You can also share it with your team so that everyone uses the same method:

  1. Take a fresh backup of the site.
  2. Decide who will use the account, for which folder and for how long.
  3. Create the account on the FTP Accounts screen with a username, domain, strong password, narrow directory and suitable quota.
  4. Connect in FileZilla through Site Manager with explicit TLS required, port 21 and passive mode.
  5. If you hit an error, check the full username first, then the password, then the network and passive mode.
  6. Send the credentials through separate channels and note the end date.
  7. When the work ends, remove the account with Delete Account, not Delete Account and Files.

In short, a well-managed FTP account lets the work happen without leaving your site exposed. A forgotten account, on the other hand, carries risk even years later. That is why we treat the closing step as part of the process, just like the setup.

Frequently Asked Questions

Are cPanel FTP account details the same as my cPanel login?
No, an extra cPanel FTP account has its own username and password, separate from your cPanel login. Only the main FTP account matches your cPanel username and password. That is why you create an extra account when you work with someone outside your team. They reach only the folder you choose, not your email or database settings.
Why is the FTP username in the user@domain format?
Because cPanel ties each extra FTP account to the domain you select, and the login combines the username with that domain. If you type only the short name in FileZilla, the server usually returns a 530 error. Copy the full name from the list on the FTP Accounts screen and paste it into the client's user field.
Can I use SFTP with an extra FTP account?
Usually not. SFTP is a separate protocol that runs over SSH, not FTP, and it needs an account user with SSH access. In most setups, extra FTP accounts are not SSH users. If you want an encrypted connection with an extra account, use FTPS with explicit TLS. To get SSH turned on, contact your hosting provider.
Should I use port 21 or port 22?
Port 21 is the standard for FTP and for FTPS with explicit TLS. SFTP runs over SSH, so it uses port 22 by default, although some hosts change it. The safest way is to check your host's help page or ask their support team which port is open. Avoid guessing, since repeated failed attempts can get your IP blocked.
Will deleting the account also delete my files?
No, the Delete Account option removes only the FTP account and leaves the files alone. The Delete Account and Files option, however, also removes the files in the account's directory. If that directory is broad, like public_html, it can wipe your site. When you close a temporary account, delete only the account and take a backup first.
How long should an FTP account stay open?
Keep it open only as long as the work lasts. When a one-time migration or fix ends, delete the account the same day. If you need ongoing maintenance, you can keep it, but change the password at regular intervals and keep a list of who has access. Unused accounts carry needless risk, like a door nobody remembers.
  • cPanel
  • FTP account
  • FileZilla
  • FTPS
  • SFTP
  • hosting security
  • website management
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.